SBOM

Your supply chain, on the same thread.

Import CycloneDX or SPDX and every component becomes a first-class item — linked to the risks it threatens and the tests that cover it, with CVE and CVSS tracking and suspect propagation when a new vulnerability lands. The supply chain joins the same connected record as everything else.

TraceUnified SBOM view

Components as first-class items — with CVE / CVSS tracking, license policy, and suspect propagation when a new vulnerability is disclosed.

What it does

The supply chain, no longer a document apart.

An SBOM is usually filed away and consulted only when a vulnerability makes the news. Here it is on the thread — traceable, governed, and live.

CycloneDX & SPDX import

Import a standard SBOM and every component becomes a first-class item in the same connected record as your requirements, tests, and risks.

CVE & CVSS tracking

Each component carries its vulnerability information, so the security posture of your supply chain is visible in context — and tied to what depends on it.

License policy & attestation

The same governance extends to the legal dimension of the supply chain, with license policies and attestation.

Suspect propagation

When a new CVE lands, suspect status propagates to the items that depend on the affected component — turning a supply-chain event into a specific, actionable list.

On the thread

A new CVE becomes a list, not a hunt.

Because components are linked into the thread, a disclosed vulnerability points straight at what to re-examine — FDA-cybersecurity-relevant capability, built in.

derived from → Architecture

A component inventory can be proposed from the model, then completed by a human.

threatens → Risk

A component vulnerability propagates suspect status to the risks that depend on it.

covered by → Tests

Components link to the verification that covers them, so security posture ties back to evidence.

Derive with AI

Derive a component inventory from your model.

The governed derivation engine proposes an SBOM component inventory from your architecture — it builds the structure and cites its sources, but it will not fabricate versions, hashes, suppliers, or licenses. You supply those facts and accept.

ArchitectureSBOM Inventory
See how derivation is governed →

Govern your supply chain like everything else.

Bring your SBOM onto the thread — tracked, traced, and ready to react the moment a new vulnerability is disclosed.